SA8000:2014 - Social Accountability Standard
Management System

SA8000:2014 - Social Accountability Standard SAEIGHT-7: Management System, Worker Engagement, Continuous Improvement

Per SA8000:2014 Element 9: management system. Requirements include (a) Management System with senior management responsibility + (b) Worker Engagement + worker representative + (c) supplier management + (d) corrective + preventive actions + (e) continuous improvement + (f) maintain documented management system + audits.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 100 controls across 55 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISO-20400-6.5 Monitoring and continuous improvement
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO/IEC 27003:2017 · 4 controls

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P2-S1 Partnership

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services
  • ISO-15189-8.1 General requirements

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • RMI-DD-3 Red Flag Review
  • RMI-MS-2 Cobalt Standard
  • RMI-RMAP-2 Risk-Based Audit Approach
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AS9100D-10.2 Nonconformity and Corrective Action
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • IEC62304-4.1 Quality Management System
  • IEC62304-9.6 Analyze Problems for Trends
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO-41001-10.1 Nonconformity and corrective action
  • ISO-41001-8.4 Control of outsourced processes and services
  • ISO-17025-8.1 Options
  • ISO-17025-8.7 Corrective actions
  • NFPA1600-7.2 After-Action Reporting
  • NFPA1600-8.2 Corrective Action
  • 2.5.2 Verification Activities
  • 2.7.2 Food Fraud Plan

SWIFT CSCF · 2 controls

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)

South Korea ISMS-P · 2 controls

  • ISMSP-MS-04 Management Review and Improvement
  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • ACQS-8-3 Continuous Improvement
  • Clause 3 Suppliers and service providers
  • ACQ.4 Supplier Monitoring
  • Mat 03 Responsible Sourcing of Materials
  • DIQ-2 Data Quality Management
  • IS.AR.210 Findings and Corrective Actions
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ISO-14064-1-8 Quality management of the GHG inventory

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices

ISO 30401 · 1 control

  • ISO30401-15 Nonconformity and corrective action
  • ISO-39001-10.1 Nonconformity and corrective action
  • ISO-50001-8.3 Procurement

ISO 56002 · 1 control

  • ISO-56002-10.2 Deviation, nonconformity and corrective action

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.6 AI System Security

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/IEC 27014:2020 · 1 control

  • 27014-5.6 Continuous improvement

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity
  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets

SASB Standards · 1 control

  • SASB-1 Business Model + Innovation (BMI)
  • IM8-TPM.4 Supply Chain Risk Management
  • UKGAMBLE-4 Resilience and Incident Response
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 100 it maps to, and the evidence behind each claim, over MCP and REST.